Trojan

Trojan.Win32.Agentb.ixji removal guide

Malware Removal

The Trojan.Win32.Agentb.ixji is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agentb.ixji virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Anomalous binary characteristics

Related domains:

shell.view
godz.bit

How to determine Trojan.Win32.Agentb.ixji?


File Info:

crc32: 372ED4CF
md5: 42a1a325dfa4f06b43060f8760c48f36
name: 42A1A325DFA4F06B43060F8760C48F36.mlw
sha1: 6aa265f9dfe11f8cd49cd85abca6958f4b1d6a0a
sha256: afb35551d90a61ddd32da65cbd208a052c964b3d268ad78716dc1fce5b6a5690
sha512: 8c1fd49978e7277ed4588392910057c8f4e3560add7388c1687088cfe5ee72f69127ef475366c9a79f73651191627ab19c28c06c502e0e92efbc5c025e60bced
ssdeep: 3072:YkVVEHHg4ZAfQBpDrAuzq1C756TZKdIBNGcXu1V/Q8kC98LaWTRfs:YkVUHggLrSA6TZT5u1VFkC98LaWTps
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Agentb.ixji also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Bot.3503
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MauvaiseRI.S5252937
ALYacTrojan.Mint.Jamg.C
MalwarebytesMalware.AI.1898326176
ZillyaTrojan.GandCrypt.Win32.75
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.5dfa4f
CyrenW32/S-15f730e0!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GDJU
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Agentb.ixji
BitDefenderTrojan.Mint.Jamg.C
NANO-AntivirusTrojan.Win32.Scar.eyebey
ViRobotTrojan.Win32.Ransom.314880.G
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanTrojan.Mint.Jamg.C
TencentWin32.Trojan.Agentb.Pcir
Ad-AwareTrojan.Mint.Jamg.C
SophosMal/Generic-S + Mal/GandCrab-B
ComodoTrojWare.Win32.Ransom.GandCrypt.C@7ivv6t
BitDefenderThetaGen:NN.ZexaF.34758.muW@aSel0@i
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_EMOTET.SMB1
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.42a1a325dfa4f06b
EmsisoftTrojan.Mint.Jamg.C (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.GandCrypt.x
AviraHEUR/AGEN.1117310
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.248F841
MicrosoftRansom:Win32/Gandcrab.SF!MTB
ZoneAlarmTrojan.Win32.Agentb.ixji
GDataTrojan.Mint.Jamg.C
AhnLab-V3Trojan/Win32.Agentb.C2428130
Acronissuspicious
McAfeeGenericRXEC-CN!42A1A325DFA4
MAXmalware (ai score=99)
VBA32BScope.TrojanRansom.GandCrypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_EMOTET.SMB1
RisingMalware.Obscure!1.A3BB (CLASSIC)
IkarusTrojan.Crypt
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.HCUD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.Agentb.ixji?

Trojan.Win32.Agentb.ixji removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment